Open Bug 2069766 Opened 7 days ago Updated 2 days ago

DigiCert: CPR subject.countryName

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

ASSIGNED

People

(Reporter: dcbugzillaresponse, Assigned: dcbugzillaresponse)

Details

(Whiteboard: [ca-infosharing])

User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 Edg/151.0.0.0

Steps to reproduce:

Preliminary Incident Report

Summary

  • Incident description:

On September 5, 2026 at 07:00 UTC DigiCert received the following email through our certificate problem reporting system:

all cas email

cabf baseline-requirement doc - https://github.com/cabforum/servercert/blob/main/docs/BR.md say -

Country: Either a member of the United Nations OR a geographic region recognized as a Sovereign State by at least two UN member nations.

https://www.un.org/en/about-us/member-states

on censys.com - many cas issued with country that not meet this definition and so mis-issue

please check make bugzilla and revoke country with no un recognized status -

ai, as, aw, ax, bl, bm, bq, ck, cw, fo, gf, gg, gi, gl, gp, gu, hk, im, je, ky, mo, mp, , q, ms, nc, pf, pm, pr, re, sh, sx, tc, vg, vi, xx, yt

i will ask why lots of cas make difficult to find problem-report email? in my country many sites block also.

  • Relevant policies:
    Baseline Requirements v2.2.9 Section 1.6.1, 7.1.2.7.3, and 7.1.2.7.4
  • Source of incident disclosure: Third party

As per ISO - ISO 3166 — Country Codes the 3166-1 country codes are derived from data which is sourced from the United Nations. For the section 1.6.1 definition referenced to be normative, in the body of the requirements the word ‘Country’ must be capitalized. Where the word ‘country’ is used without being capitalized it does not reference the specific definition from section 1.6.1, and instead defaults to the common English language usage.

The word 'country' in the BR is only used in capitalized form in section 7 in reference to what to do for Countries which have NOT been assigned an ISO 3166-1 code.[TH1.1][RS1.2] All other requirements within the BR use lower case 'country' and therefore are specifically NOT subject to the very particular definition contained in the document. This limited scope is intentional. During the discussion leading up to the inclusion of the allowance of usage of the user defined ‘XX’ country code, consensus was strong that neither the CA/Browser Forum itself, nor any of its individual members had any desire to be dragged into geopolitical struggles. As such, it has been long accepted practice to allow the usage of the ISO 3166-1 country code list as the default allowed list of acceptable values in the subject.CountryName field even for geographic regions which may not be fully independent countries and only delve into geopolitics in cases where there might be a legitimate argument to be made that a country exists without a corresponding 3166-1 code, and only far enough to make a determination as to whether or not usage of the ‘XX’ code is appropriate. All that said, there have been many discussions of this topic over the years, and it continues to come up. DigiCert welcomes additional discussion at the CA/Browser Forum or other standards bodies to see if we, as a community, can come up with better or clearer standards to address this topic.

We do not consider this a compliance incident, therefore no certificates have been misissued and we request this bug be closed as INVALID.

Flags: needinfo?(incident-reporting)

Sorry, the link didn't carry over to the page where ISO talks about where the data for the 3166 list comes from. It is here.

Whiteboard: [ca-infosharing]
Assignee: nobody → dcbugzillaresponse
Status: UNCONFIRMED → ASSIGNED
Type: defect → task
Ever confirmed: true
Flags: needinfo?(incident-reporting)

GoDaddy received the same Certificate Problem Report and, after reviewing the issue, agrees with DigiCert’s interpretation and conclusions. We likewise do not consider the use of the identified ISO 3166-1 alpha-2 codes in the countryName field to constitute misissuance. We agree that the defined term ‘Country’ applies where that defined term is used in the criteria, while the certificate profile requirements for countryName specifically reference ISO 3166-1. We also agree that any desire to clarify or change these requirements would be better addressed through discussion within the CA/Browser Forum.

Hongkong Post received the same Certificate Problem Report as well. We have reviewed the concern and agree with DigiCert’s interpretation and conclusions.

Hongkong Post CA issues certificates only to organisations registered in Hong Kong. For these certificates, the Subject countryName attribute is populated with HK, which is the ISO 3166-1 alpha-2 code assigned to Hong Kong. Our understanding is that the use of C=HK is consistent with Section 7.1.2.7 and does not constitute misissuance.

As the matter involves the interpretation of the relationship between the BR definition of “Country” and the Subject countryName requirements, we would appreciate clarification or a change by the CA/Browser Forum.

You need to log in before you can comment on or make changes to this bug.